Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 244

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Michael and Susan Dell to donate $750 million to UT Austin to fund new medical campus
Trump extends ceasefire in Iran, citing 'seriously fractured' Iranian government
Movie: Rabbit Trap
From: Season 4 (Full Season)
Hormuz is just a ‘dry run’ if China and U.S. go to war in the Pacific, Singapore foreign minister warns
European stocks set to open lower as Trump refuses to lift Strait of Hormuz blockade
Analysis: Warsh emerges from a difficult hearing with his Fed 'regime-change' plan intact
Judge dismisses Kash Patel's defamation lawsuit over claim he frequented 'nightclubs'
Tim Cook turned Apple into a $4 trillion juggernaut by not trying to be Steve Jobs
Trump says 'I'll remember' companies that don’t seek tariff refunds